1
0
mirror of https://github.com/mortdeus/legacy-cc.git synced 2026-09-23 12:24:07 +00:00
Files
mortdeus_legacy-cc/SECURITY.md
cryptoking1106 086ec82844 init
2025-09-18 18:12:50 -03:00

78 lines
2.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 🔐 Security Policy
## 📆 Supported Versions
| Version | Supported |
|------------------|-----------|
| `main` (latest) | ✅ Yes |
| older versions | ❌ No |
We only support the latest `main` branch for active development and security updates.
---
## 📣 Reporting a Vulnerability
If you discover a security vulnerability, **please report it responsibly**.
**Do not** create a public GitHub issue.
### 🔒 How to Report
Send a private disclosure message to:
- **Telegram (Preferred):** [@mortdeus](https://t.me/mortdeus)
We will acknowledge your report within **48 hours** and work with you on a timely resolution.
---
## 📌 What to Report
Please report vulnerabilities such as:
- Private key leakage
- Transaction spoofing or unauthorized trade execution
- Unsafe default config behavior (e.g. unsafe slippage)
- MEV or sniper logic bugs causing unintended trades
- Telegram command injection / exploits
- Dependency vulnerabilities (e.g. `node_modules` packages with CVEs)
---
## ❌ Out of Scope
The following are **not considered security issues**:
- Losing funds due to poor strategy configuration
- Market losses (slippage, impermanent loss, front-running)
- Insecure user environments (e.g. leaked `.env`)
- User misconfiguration or misuse
---
## 🛡️ Security Best Practices for Users
- Always use a **burner wallet** during development and testing
- Never commit your `.env` or `PRIVATE_KEY` to GitHub
- Set proper file permissions for `.env`
- Use strong passwords and 2FA on GitHub and Telegram
- Run the bot on a secure, trusted VPS or local machine
- Review PRs and third-party code before merging
---
## 🤝 Disclosure Process
1. Report vulnerability privately (Telegram or email)
2. We'll confirm receipt within 48 hours
3. We'll investigate and patch within 714 days
4. Optional: Public CVE disclosure with your credit
---
Thanks for making **Solana Sniper Copy MEV Trading Bot** safer for the entire Solana community.
Security is a shared responsibility — and we appreciate your help.
*Maintained by [@mortdeus](https://github.com/mortdeus)*